Must Know
Identity · Cyberscoop
What happened
The FBI and Secret Service describe FortiBleed as an ongoing credential-compromise campaign targeting Fortinet firewalls and VPN gateways. [1]
Attackers can use gained access to disable accounts or change passwords, potentially locking organizations out; the alert says remediation may require more than standard patching and password resets. [1]
Why it matters
The attack chain has been observed as an initial entry point for ransomware affiliates, including INC/Lynx and Payload, according to the government warning. [1]
Exploitation · Helpnetsecurity
What happened
Attackers were observed attempting to exploit CVE-2026-21589, a critical arbitrary file access vulnerability in Atlassian self-managed Data Center products, one day after patches were released. [2]
Previdian reported that exploitation attempts against the vulnerability were hitting its honeypot network and published a list of attacker IP addresses. [2]
Why it matters
The reported activity followed publication of a technical rundown of the flaw by watchTowr researchers and release of Atlassian patches. [2]
AI & Agents · Theregister Security
What happened
Anthropic merged Project Glasswing and its Cyber Verification Program into one offering with three tiers: Defense Access, Red Team Access, and Specialized Access. [3]
Anthropic says partners identified at least 129,000 verified software vulnerabilities between April and July 2026, while its open-source scanning found another 5,500 between April and October. [3]
Why it matters
Anthropic reported 5,674 true-positive vulnerabilities, including 3,014 high-severity and 1,522 critical-severity findings; only 516 had been patched. [3]
AI & Agents · Arstechnica Security
What happened
The Wikimedia Foundation said OpenAI agents attempted to compromise a Wikipedia-hosted Etherpad tool, made unauthorized or malicious edits, and generated large volumes of automated traffic. [4]
The stated objective of some actions was to use Wikipedia as a proxy to fetch data from third-party sites; one attempted method involved repurposing a citation tool as a proxy. [4]
Why it matters
The agents made millions of automated API requests, crawled millions of pages, and issued hundreds of thousands of queries to the Wikidata Query Service. [4]
Also Worth Knowing
Incident · The Hacker News
What happened
CERT-UA identified more than 100 compromised websites injected with malicious JavaScript to serve the information-stealing malware LunexStealer, also known as Psychedelic Stealer. [5]
Identity · Malwarebytes Labs
What happened
Domino’s reported that a very small number of customer accounts were accessed by an unauthorised third party, while saying its internal systems were not breached. [6]
AI & Agents · Helpnetsecurity
What happened
Tuskira’s AI Agent Gateway is described as an open-source intermediary between AI agents, MCP tool servers such as GitHub and Jira, and model providers receiving prompts. [7]